{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-17191", "assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7", "state": "PUBLISHED", "assignerShortName": "Arista", "dateReserved": "2026-07-24T19:03:13.728Z", "datePublished": "2026-07-27T16:41:17.436Z", "dateUpdated": "2026-07-27T17:29:45.538Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7", "shortName": "Arista", "dateUpdated": "2026-07-27T16:41:17.436Z" }, "title": "VeloCloud Orchestrator Flow Metrics API SQL Injection", "datePublic": "2026-07-27T16:37:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-89", "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-66", "descriptions": [ { "lang": "en", "value": "CAPEC-66: SQL Injection" } ] } ], "affected": [ { "vendor": "Arista Networks", "product": "VeloCloud Orchestrator On-Prem", "versions": [ { "status": "affected", "version": "5.2.0", "lessThan": "5.2.3.14", "versionType": "custom" }, { "status": "affected", "version": "6.1.0", "lessThan": "6.1.3.4", "versionType": "custom" }, { "status": "affected", "version": "6.4.0", "lessThan": "6.4.2.4", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections.\n\n\n\n\nThis issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections.

\n

This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

" } ] } ], "references": [ { "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24365-security-advisory-0145", "name": "Security Advisory 0145", "tags": [ "vendor-advisory" ] } ], "configurations": [ { "lang": "en", "value": "A successful attack requires a valid authenticated session on the VCO portal. The minimum user role required is Enterprise Read Only, the lowest built-in tenant role. No non-default configuration is required.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

A successful attack requires a valid authenticated session on the VCO portal. The minimum user role required is Enterprise Read Only, the lowest built-in tenant role. No non-default configuration is required.

" } ] } ], "workarounds": [ { "lang": "en", "value": "Until the fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment:\n\n\n\n * Restrict access to the VCO web interface to trusted administrative networks.\n\n * Monitor the VCO for accesses from known malicious source IPs.\n\n * Monitor for unexpected outbound network activity from the VCO host.\n\n * Review recent administrator activity for unexpected changes.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

Until the fixed software is deployed, operators should apply defense-in-depth controls appropriate for their environment:

\n" } ] } ], "solutions": [ { "lang": "en", "value": "The recommended resolution is to upgrade to a fixed VCO release at your earliest convenience.\n\n\n\n\nThese vulnerabilities have been fixed in the following releases:\n\n\n\n * VCO 5.2.3.14 and later in the 5.2 train\n\n * VCO 6.1.3.4 and later in the 6.1 train\n\n * VCO 6.4.2.4 and later in the 6.4 train", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

The recommended resolution is to upgrade to a fixed VCO release at your earliest convenience.

\n

These vulnerabilities have been fixed in the following releases:

\n" } ] } ], "source": { "defect": [ "BUG 1568507" ], "advisory": "145", "discovery": "INTERNAL" }, "x_generator": { "engine": "Vulnogram 1.0.4" }, "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "availabilityImpact": "LOW", "baseSeverity": "CRITICAL", "baseScore": 9.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L" } }, { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "subConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "LOW", "subIntegrityImpact": "LOW", "vulnAvailabilityImpact": "LOW", "subAvailabilityImpact": "LOW", "exploitMaturity": "NOT_DEFINED", "Safety": "PRESENT", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "HIGH", "baseScore": 8.5, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/S:P" } } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-07-27T17:29:37.640962Z", "id": "CVE-2026-17191", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-07-27T17:29:45.538Z" } } ] } }